Compliance / Swootle Research / 2026-07-18
An operational Australian Tranche 2 checklist covering scope, governance, CDD, risk, reporting, training, monitoring, records and control testing.
Tranche 2 AML requirements checklist for Australian firms operating now
Tranche 2 AML requirements are an operating set of scope, governance, customer due diligence, risk, reporting, training, monitoring, and record controls. The new regime for newly regulated sectors commenced on 1 July 2026. A checklist is useful only when each item has an owner, an approved procedure, evidence of execution, and a review path for exceptions.
This is general information, not legal advice. It is an operational checklist, not a vendor comparison. Use AML/CTF implementation in Australia for the broad commercial implementation pathway, AUSTRAC Tranche 2 software for procurement and supplier evidence, and AML software for accountants in Australia for the accountant-specific workflow evaluation.
1. Confirm whether the business is in scope
AUSTRAC says a business is regulated when it provides a designated service with the relevant Australian geographical link. Scope follows the service and the facts, not simply the sector name.
- [ ] List every service that may fall within the designated-service tables, including services provided as part of a broader engagement.
- [ ] Identify the customer for each service and the relevant Australian connection.
- [ ] Check current AUSTRAC guidance for exemptions, exceptions, and service-specific examples.
- [ ] Record the basis for an in-scope conclusion and the person who approved it.
- [ ] If the business considers itself out of scope, record the services reviewed, the reasoning, the AUSTRAC guidance relied on, and any independent advice used.
- [ ] Confirm the applicable AUSTRAC enrolment or registration requirement and timing for the business. Do not copy a date used for an initial cohort into every policy; follow current AUSTRAC Online guidance and the business’s actual service date.
Useful starting points are AUSTRAC’s designated services for newly regulated entities, check if you may be regulated, and the current Anti-Money Laundering and Counter-Terrorism Financing Act 2006.
2. Establish governance and an AML/CTF program
The program must be usable by the people who make decisions, not only stored as a policy document. AUSTRAC’s current program guidance describes risk assessment, documented policies, senior approval, review, records, independent evaluation, a compliance officer, governance roles, and trained personnel.
- [ ] Complete and approve a business-level ML/TF risk assessment covering customers, services, delivery channels, jurisdictions, products, transactions, and other relevant factors.
- [ ] Document the AML/CTF program, including policies, systems, controls, procedures, escalation, reporting, records, training, and review triggers.
- [ ] Appoint an AML/CTF compliance officer and define the governing body, senior manager, decision rights, and cover arrangements.
- [ ] Set the program review process and the circumstances that require an update, including changes in services, risk, law, AUSTRAC guidance, or operating model.
- [ ] Set the independent-evaluation frequency appropriate to the nature, size, and complexity of the business. AUSTRAC’s guidance states a minimum three-year frequency, while transitional rules can affect a newly regulated entity’s first evaluation timing.
- [ ] Keep senior approvals, version history, review rationale, and evaluation outcomes as records.
Do not treat a starter kit as a universal answer. AUSTRAC says its program starter kits are designed for eligible reporting entities and must be considered and customised for the practice’s circumstances.
3. Define initial customer due diligence
Initial CDD is the controlled starting point for the customer relationship. AUSTRAC’s overview says firms generally conduct initial CDD before providing a designated service, with specific rules for limited exceptions and delayed CDD.
- [ ] Define the customer types and service contexts the business handles.
- [ ] Specify the KYC information to collect and verify for each customer type.
- [ ] Identify the people associated with the customer and the ownership, control, authority, or trust roles the program requires the business to understand.
- [ ] Capture the nature and purpose of the business relationship or occasional transaction.
- [ ] Define when enhanced CDD, simplified CDD, reliance, or delayed CDD may be used and who approves the decision.
- [ ] Set the response to missing, inconsistent, expired, or unverifiable information.
- [ ] Prevent the business from proceeding where the program or applicable law requires CDD to be completed first.
- [ ] Record what was requested, received, verified, returned, accepted, rejected, and escalated.
The AUSTRAC initial CDD guidance links to customer-type-specific requirements. Do not turn an illustrative evidence list into a universal rule for every customer or service.
4. Configure risk assessment and enhanced review
Risk assessment should explain decisions rather than produce an unexplained label. The firm’s risk model should match its own customers, services, channels, jurisdictions, ownership structures, and expected activity.
- [ ] Define the risk factors and the evidence or information that supports each factor.
- [ ] Configure routes for standard, higher-risk, incomplete, and exceptional cases.
- [ ] Define when enhanced CDD, additional source information, senior approval, or a refusal to proceed is required.
- [ ] Give reviewers the relevant service, customer, relationship, evidence, risk, and prior-decision context.
- [ ] Require a rationale when a reviewer overrides, accepts with conditions, returns, rejects, or escalates a configured route.
- [ ] Test the model against a straightforward individual, a layered company, a trust, an overseas connection, a PEP or sanctions result, and a client who will not provide ownership information.
A configured risk score is not a legal conclusion or an automatic clearance. The accountable business decides whether the file fits its risk appetite and approved program.
5. Define reporting and escalation
Staff need a path from an observation to a timely decision. A workflow can route an internal concern, but it does not automatically decide that an SMR is required or submit one unless a separately verified reporting implementation does so.
- [ ] Define red flags and unusual transactions or behaviour relevant to the business’s services.
- [ ] Train personnel to record the concern, relevant facts, evidence, and date of escalation.
- [ ] Route concerns to the AML/CTF compliance officer or other authorised decision-maker.
- [ ] Record the review, decision, rationale, and any follow-up or enhanced CDD action.
- [ ] Confirm who submits an SMR through AUSTRAC Online, using the current form and process.
- [ ] Record the applicable reporting timeframe. AUSTRAC currently states 24 hours after forming the suspicion for terrorism-financing matters and 3 business days for other suspicions, with specific exceptions and transition arrangements.
- [ ] Give staff clear tipping-off and confidentiality instructions.
See AUSTRAC’s current suspicious matter reporting guidance for the reporting obligation, timing, forms, and process.
6. Build a record-keeping model
Record keeping is a control with its own ownership, retention, access, and retrieval design. It is not a promise that a software product will automatically create a complete audit record.
- [ ] Identify the AML/CTF program, CDD, transaction, enrolment, training, approval, escalation, evaluation, and monitoring records the business must keep.
- [ ] Link each record to the customer, service, transaction, decision, or control it supports.
- [ ] Preserve relevant versions, timestamps, authors, reviewer identity, source documents, provider results, comments, and rationale.
- [ ] Define the retention period by record class and confirm it against the current Act, Rules, AUSTRAC guidance, privacy obligations, and any other applicable requirement.
- [ ] Test retrieval for a completed file, an incomplete file, a changed relationship, a reported suspicion, and an earlier version of the program.
- [ ] Define access, security, export, backup, correction, deletion, and supplier-exit responsibilities.
- [ ] If a provider stores records, document the arrangement, scope, availability, access, and return or deletion process.
AUSTRAC’s record-keeping overview distinguishes program, CDD, and transaction records and explains that retention periods depend on the record type and circumstance. Use it as the current operational reference rather than assuming one blanket period.
7. Separate provider checks from internal controls
Identity, entity, registry, PEP, sanctions, adverse-media, transaction-monitoring, and other checks may be supplied by different services or performed by staff. The checklist should make that dependency visible.
- [ ] Name each provider, data source, coverage, jurisdiction, integration, credential owner, and commercial dependency.
- [ ] Define what a result means, what it does not establish, and what happens when the result is unavailable, ambiguous, or a possible match.
- [ ] Link each result to the correct individual, entity, relationship, service, or transaction.
- [ ] Assign the human reviewer and record how a false positive, discrepancy, or unresolved result is handled.
- [ ] Define provider outage, data correction, refresh, and change-management procedures.
- [ ] Do not describe a workflow field or document upload as screening execution, verification, monitoring, or reporting.
8. Train personnel on decisions and confidentiality
Training should enable people to use the program in live work. It should include:
- [ ] when the business’s designated-service controls apply;
- [ ] how to start the correct customer and service flow;
- [ ] what information and evidence to request;
- [ ] how to handle gaps, contradictions, possible matches, and higher-risk indicators;
- [ ] when to escalate and who can approve, reject, or report;
- [ ] how to document a decision without revealing a suspicion to the customer; and
- [ ] how to protect personal information and use the firm’s record systems.
Test training with a normal matter, a complex ownership structure, a trust, an uncertain provider result, a suspicious-activity scenario, and a customer who refuses an important request.
9. Operate ongoing CDD and monitoring
Ongoing CDD is not limited to a scheduled re-collection form. AUSTRAC says businesses must monitor customers to identify, assess, manage, and mitigate ML/TF risk, and for ongoing relationships review and, where appropriate, update KYC information and customer risk.
- [ ] Define the data sources and processes used to monitor transactions and customer behaviour.
- [ ] Set risk-based thresholds, triggers, review responsibilities, and escalation paths.
- [ ] Define event-driven review for changes in ownership, control, authority, service, jurisdiction, expected activity, or risk information.
- [ ] Link unusual activity to investigation, enhanced CDD, reporting, and record procedures where relevant.
- [ ] Check that monitoring is operating effectively and document assurance or control testing.
- [ ] Distinguish a configured refresh workflow from continuous external monitoring or screening supplied by another provider.
Read AUSTRAC’s ongoing CDD overview and how to monitor your customers guidance for the current distinction between monitoring, review, escalation, and records.
10. Test the operating model and assign ownership
Use a staged operating plan rather than a fixed calendar promise. Each stage should have an owner, an expected output, a test case, and an approval or remediation decision.
| Stage | Required output |
|---|---|
| Scope and governance | Service matrix, Australian connection, risk assessment, program, compliance officer, senior approvals, and enrolment position. |
| CDD and risk design | Customer-type paths, evidence rules, relationship model, risk factors, enhanced-review routes, and decision rights. |
| Reporting and records | Escalation process, authorised reporting route, record model, retention map, access controls, and retrieval test. |
| Training and pilot | Trained staff, representative scenarios, provider failure tests, reviewer calibration, and recorded findings. |
| Live operation and review | Control monitoring, issue management, program updates, independent-evaluation plan, and evidence that owners are performing their roles. |
The checklist is complete only when the responsible people can operate the approved controls and explain the remaining assumptions. It is not a certification of compliance or readiness.
How this checklist relates to software
The operational owner is the firm’s AML/CTF program and control model. Software may help coordinate intake, evidence, configured risk routes, review, approvals, and change work, but it does not replace scope analysis, legal interpretation, provider checks, monitoring data, reporting decisions, or accountable governance.
For a broad commercial implementation conversation, use AML/CTF implementation in Australia. For supplier demonstrations, boundaries, scoring, and procurement evidence, use the AUSTRAC Tranche 2 software buyer guide. For an accountant-specific evaluation, use AML software for accountants in Australia.
Frequently asked questions
What belongs on a Tranche 2 AML requirements checklist?
Include service scope, Australian connection, enrolment position, AML/CTF program governance, compliance officer, personnel controls, initial and ongoing CDD, risk assessment, enhanced CDD, reporting and escalation, records, monitoring, independent evaluation, and control testing.
Is a template enough for Tranche 2 AML/CTF obligations?
No. A template can structure the work, but the business must customise its program, assign owners, train staff, operate customer flows, make accountable decisions, report when required, and keep the relevant records.
Is there one enrolment deadline for every newly regulated business?
Do not assume that. Follow AUSTRAC’s current enrolment guidance and the timing applicable to the business’s designated service and circumstances. A date used for an initial cohort should not be copied into every business policy.
Does the checklist mean a business is ready or compliant when every box is ticked?
No. The business must verify that its controls fit its services and risks, are operating as designed, and are supported by appropriate evidence and accountable decisions. A checklist or software product cannot certify that outcome automatically.
What is the biggest implementation risk?
The biggest risk is a policy that does not translate into daily work. Staff need a controlled path for scope, customer due diligence, evidence, risk, review, escalation, reporting, monitoring, and records, with clear ownership when information is missing or circumstances change.
Put the guide into practice
Map this operational checklist to a representative workflow
Bring one anonymised representative case. We will map the customer request, evidence, exceptions and accountable decision, then identify whether Swootle fits the operating model.